Google IAM Policy Troubleshooter says allowed, but a storage request still fails
0 reputation · 18 Nov 2021, 06:55 UTC
A service’s storage request is denied. In this illustrative case, Policy Troubleshooter reports that the named principal has the permission on the resource. The team has not checked whether the actual call crosses a VPC Service Controls boundary. Does the allowed result settle the whole access question?
- Environment
- Editorial worked example. See the question for the scenario and assumptions.